CVE-2016-4003
medium · 6.1Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded parameter.
6.1
CVSS
11.6%
EPSS (exploit prob.)
96th
EPSS percentile
2016-04-12
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | struts | >= 2.0.0, <= 2.3.24.1 |
Check a specific version with /api/v1/cve/match.
References
- http://struts.apache.org/docs/s2-028.html
- http://www.securityfocus.com/bid/86311
- http://www.securitytracker.com/id/1035268
- https://issues.apache.org/jira/browse/WW-4507
- http://struts.apache.org/docs/s2-028.html
- http://www.securityfocus.com/bid/86311
- http://www.securitytracker.com/id/1035268
- https://issues.apache.org/jira/browse/WW-4507
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-4003